Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-g48c-2wqr-h844 | LangGraph checkpoint loading has unsafe msgpack deserialization |
Tue, 21 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain
Langchain langgraph |
|
| CPEs | cpe:2.3:a:langchain:langgraph:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Langchain
Langchain langgraph |
Fri, 06 Mar 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Langchain-ai
Langchain-ai langgraph |
|
| Vendors & Products |
Langchain-ai
Langchain-ai langgraph |
Thu, 05 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, via aiosqlite). In version 1.0.9 and prior, LangGraph checkpointers can load msgpack-encoded checkpoints that reconstruct Python objects during deserialization. If an attacker can modify checkpoint data in the backing store (for example, after a database compromise or other privileged write access to the persistence layer), they can potentially supply a crafted payload that triggers unsafe object reconstruction when the checkpoint is loaded. No known patch is public. | |
| Title | LangGraph: Unsafe msgpack deserialization in LangGraph checkpoint loading | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-06T18:04:29.687Z
Reserved: 2026-02-26T01:52:58.734Z
Link: CVE-2026-28277
Updated: 2026-03-06T18:04:26.192Z
Status : Analyzed
Published: 2026-03-05T20:16:15.677
Modified: 2026-04-21T15:14:55.870
Link: CVE-2026-28277
No data.
OpenCVE Enrichment
Updated: 2026-04-16T12:15:35Z
Github GHSA